Medium severity5.4NVD Advisory· Published Jul 8, 2022· Updated Jun 17, 2026
CVE-2022-31290
CVE-2022-31290
Description
A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
idno/knownPackagist | <= 1.3.1 | — |
Affected products
3Patches
Vulnerability mechanics
References
7- blog.jitendrapatro.me/multiple-vulnerabilities-in-idno-known-php-cms-software/nvdExploitThird Party Advisory
- docs.withknown.com/en/latest/install/index.htmlnvdProductVendor AdvisoryWEB
- github.com/advisories/GHSA-g688-7j3c-h9f3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-31290ghsaADVISORY
- withknown.comnvdProductVendor Advisory
- blog.jitendrapatro.me/multiple-vulnerabilities-in-idno-known-php-cms-softwareghsaWEB
- withknown.comghsaWEB
News mentions
0No linked articles in our index yet.